Remote TPM Enablement via Networked Administration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enabling a Trusted Platform Module (TPM) on a computer system in a networked environment is a time-consuming process requiring physical presence of a system administrator to manually configure each user or client computer via BIOS administrative console, lacking an efficient remote security enablement method.

Innovation Solution

A system and method for remote security enablement that establishes a communication session between a user client and an administration client via a network, utilizing a TPM enablement module to enable the TPM on a subsequent boot of the user client, incorporating a security module for authentication and a remote TPM enablement module to configure TPM settings, allowing for remote deployment and management of TPMs across multiple clients.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical presence is required for TPM enablement via BIOS administrative console, then security requirements are met, but time consumption and operational complexity increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a network-based intermediary system consisting of a TPM enablement server and client software that mediates between the administrator and the remote TPM device. This intermediary enables secure remote configuration by establishing authenticated communication channels over the network, allowing TPM enablement without physical presence while maintaining security through multi-factor authentication and encrypted data transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/physical system of direct BIOS console access with a software-based network communication system. Instead of requiring physical connection to the BIOS administrative console, the system uses network protocols, authenticated sessions, and remote command execution to achieve TPM enablement, substituting physical presence with digital authentication and remote control mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If system administrator must physically visit each user computer, then direct control is achieved, but productivity and efficiency decrease

Engineering Contradiction:
Improvedirect controlVSAvoidefficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent creates a universal remote enablement system that can manage multiple TPM devices through a single centralized interface. The TPM enablement server provides multi-functional capabilities including authentication, configuration, monitoring, and management of TPM devices across the network, allowing administrators to perform all these functions from one location rather than visiting each device individually.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transitions the management operation from a one-to-one physical interaction model to a one-to-many remote interaction model by adding the network dimension. The administrator operates from a remote location, accessing multiple TPM devices through network connections, effectively changing the spatial dimension of the operation from local physical presence to distributed network access.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If remote enablement is implemented, then time efficiency improves, but security risks and authentication complexity increase

Engineering Contradiction:
Improvetime efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary authentication and authorization actions before allowing TPM configuration operations. The system performs multi-factor authentication, verifies administrator credentials, establishes secure communication channels, and validates device permissions before enabling remote TPM enablement. This preliminary security setup ensures that only authenticated administrators can perform sensitive operations while maintaining efficient remote access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms that provide real-time status information, authentication confirmation, and operation verification to both the administrator and the system. The feedback loop includes authentication status reporting, secure channel establishment confirmation, and TPM configuration status updates, allowing the system to monitor and verify security measures while maintaining efficient remote operation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7568225B2System and method for remote security enablement
Publication Date: 2009.07.28 WORKDAY INC
  • US7568225B2 patent drawing
  • US7568225B2 patent drawing
  • US7568225B2 patent drawing

AI summary

A system for remote security enablement comprises a trusted platform module (TPM) disposed on a user client and an administration client adapted to access, via a communication network, the user client to cause enablement of the TPM on a subsequent boot of the user client.